CVE-2018-5430
Description
The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 91 Days)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
StableCommon Consequences
Applicable Platforms
Exposure of Sensitive Information to an Unauthorized Actor
DraftCommon Consequences
Applicable Platforms
JasperReports - (Authenticated) File Read
JasperReports - (Authenticated) File Read
View Exploit Code →Jasperreports Server by Tibco
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:community:*:*:*
Jasperreports Server by Tibco
cpe:2.3:a:tibco:jasperreports_server:6.4.2:*:*:*:*:*:*:*
Jasperreports Server by Tibco
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:*
Jasperreports Server by Tibco
cpe:2.3:a:tibco:jasperreports_server:6.3.0:*:*:*:*:*:*:*
Jaspersoft Reporting And Analytics by Tibco
cpe:2.3:a:tibco:jaspersoft_reporting_and_analytics:*:*:*:*:*:aws:*:*
Jasperreports Server by Tibco
cpe:2.3:a:tibco:jasperreports_server:6.4.0:*:*:*:*:*:*:*
Jasperreports Server by Tibco
cpe:2.3:a:tibco:jasperreports_server:6.3.2:*:*:*:*:*:*:*
Jasperreports Server by Tibco
cpe:2.3:a:tibco:jasperreports_server:6.3.3:*:*:*:*:*:*:*
Jaspersoft by Tibco
cpe:2.3:a:tibco:jaspersoft:*:*:*:*:*:aws_with_multi-tenancy:*:*
Jasperreports Server by Tibco
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:activematrix_bpm:*:*